Vulnerability index

Browse CVEs

2,886 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Firefox CRITICAL 10.0
CVE-2026-2761

Sandbox escape in the Graphics: WebRender component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird …

Fix: 115.33.0 / 140.8.0+
Fix from $2,300 2026-02-24
Firefox CRITICAL 9.8
CVE-2026-2758

Use-after-free in the JavaScript: GC component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, …

Fix: 115.33.0 / 140.8.0+
Fix from $2,300 2026-02-24
Firefox CRITICAL 9.8
CVE-2026-2759

Incorrect boundary conditions in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8…

Fix: 115.33.0 / 140.8.0+
Fix from $2,300 2026-02-24
Firefox CRITICAL 9.8
CVE-2026-2762

Integer overflow in the JavaScript: Standard Library component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and …

Fix: 140.8.0 / 148.0+
Fix from $2,300 2026-02-24
Firefox CRITICAL 9.8
CVE-2026-2763

Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 14…

Fix: 115.33.0 / 140.8.0+
Fix from $2,300 2026-02-24
Firefox CRITICAL 9.8
CVE-2026-2764

JIT miscompilation, use-after-free in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox …

Fix: 115.33.0 / 140.8.0+
Fix from $2,300 2026-02-24
Firefox CRITICAL 9.8
CVE-2026-2765

Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 1…

Fix: 140.8.0 / 148.0+
Fix from $2,300 2026-02-24
Firefox CRITICAL 9.8
CVE-2026-2766

Use-after-free in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderb…

Fix: 140.8.0 / 148.0+
Fix from $2,300 2026-02-24
Firefox CRITICAL 9.8
CVE-2026-2634

Malicious scripts could cause desynchronization between the address bar and web content before a response is received in Firefox iOS, allowing attack…

Fix: 147.4+
Fix from $2,300 2026-02-24
Firefox CRITICAL 9.8
CVE-2026-2757

Incorrect boundary conditions in the WebRTC: Audio/Video component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.…

Fix: 115.33.0 / 140.8.0+
Fix from $2,300 2026-02-24
Firefox HIGH 8.8
CVE-2026-2447

Heap buffer overflow in libvpx. This vulnerability was fixed in Firefox 147.0.4, Firefox ESR 140.7.1, Firefox ESR 115.32.1, Thunderbird 140.7.2, and …

Fix: 115.32.1 / 140.7.1+
Fix from $1,950 2026-02-16
Firefox HIGH 8.8
CVE-2026-24869

Use-after-free in the Layout: Scrolling and Overflow component. This vulnerability was fixed in Firefox 147.0.2.

Fix: 147.0.2+
Fix from $1,950 2026-01-27
Firefox MEDIUM 6.5
CVE-2026-24868

Mitigation bypass in the Privacy: Anti-Tracking component. This vulnerability was fixed in Firefox 147.0.2.

Fix: 147.0.2+
Fix from $1,600 2026-01-27
Firefox CRITICAL 9.8
CVE-2026-0892

Memory safety bugs present in Firefox 146 and Thunderbird 146. Some of these bugs showed evidence of memory corruption and we presume that with enoug…

Fix: 147.0+
Fix from $2,300 2026-01-13
Firefox HIGH 8.1
CVE-2026-0891

Memory safety bugs present in Firefox ESR 140.6, Thunderbird ESR 140.6, Firefox 146 and Thunderbird 146. Some of these bugs showed evidence of memory…

Fix: 140.7.0 / 147.0+
Fix from $1,950 2026-01-13
Firefox HIGH 7.5
CVE-2026-0889

Denial-of-service in the DOM: Service Workers component. This vulnerability was fixed in Firefox 147 and Thunderbird 147.

Fix: 147.0+
Fix from $1,950 2026-01-13
Firefox MEDIUM 6.5
CVE-2026-0885

Use-after-free in the JavaScript: GC component. This vulnerability was fixed in Firefox 147, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.…

Fix: 140.7.0 / 147.0+
Fix from $1,600 2026-01-13
Firefox MEDIUM 5.4
CVE-2026-0890

Spoofing issue in the DOM: Copy & Paste and Drag & Drop component. This vulnerability was fixed in Firefox 147, Firefox ESR 140.7, Thunderbird 147, a…

Fix: 140.7.0 / 147.0+
Fix from $1,600 2026-01-13
Firefox MEDIUM 5.3
CVE-2026-0886

Incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 147, Firefox ESR 115.32, Firefox ESR 140.7, Thunderb…

Fix: 115.32.0 / 140.7.0+
Fix from $1,600 2026-01-13
Firefox MEDIUM 5.3
CVE-2026-0888

Information disclosure in the XML component. This vulnerability was fixed in Firefox 147 and Thunderbird 147.

Fix: 147.0+
Fix from $1,600 2026-01-13
Firefox CRITICAL 10.0
CVE-2026-0881

Sandbox escape in the Messaging System component. This vulnerability was fixed in Firefox 147 and Thunderbird 147.

Fix: 147.0+
Fix from $2,300 2026-01-13
Firefox CRITICAL 9.8
CVE-2026-0879

Sandbox escape due to incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 147, Firefox ESR 115.32, Firef…

Fix: 115.32.0 / 140.7.0+
Fix from $2,300 2026-01-13
Firefox CRITICAL 9.8
CVE-2026-0884

Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 147, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 1…

Fix: 140.7.0 / 147.0+
Fix from $2,300 2026-01-13
Firefox HIGH 8.8
CVE-2026-0880

Sandbox escape due to integer overflow in the Graphics component. This vulnerability was fixed in Firefox 147, Firefox ESR 115.32, Firefox ESR 140.7,…

Fix: 115.32.0 / 140.7.0+
Fix from $1,950 2026-01-13
Firefox HIGH 8.8
CVE-2026-0882

Use-after-free in the IPC component. This vulnerability was fixed in Firefox 147, Firefox ESR 115.32, Firefox ESR 140.7, Thunderbird 147, and Thunder…

Fix: 115.32.0 / 140.7.0+
Fix from $1,950 2026-01-13
Firefox HIGH 8.1
CVE-2026-0877

Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 147, Firefox ESR 115.32, Firefox ESR 140.7, Thunderbird 147…

Fix: 115.32.0 / 140.7.0+
Fix from $1,950 2026-01-13
Firefox HIGH 8.0
CVE-2026-0878

Sandbox escape due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 147, Firefox ESR …

Fix: 140.7.0 / 147.0+
Fix from $1,950 2026-01-13
Firefox MEDIUM 5.3
CVE-2026-0883

Information disclosure in the Networking component. This vulnerability was fixed in Firefox 147, Firefox ESR 140.7, Thunderbird 147, and Thunderbird …

Fix: 140.7.0 / 147.0+
Fix from $1,600 2026-01-13
Firefox CRITICAL 9.8
CVE-2025-14860

Use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 146.0.1.

Fix: 146.0.1+
Fix from $2,300 2025-12-18
Firefox HIGH 8.8
CVE-2025-14861

Memory safety bugs present in Firefox 146. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of the…

Fix: 146.0.1+
Fix from $1,950 2025-12-18